Site sprawl needs an owner before it needs a policy
Give a Microsoft 365 tenant a few years of self-service and it fills with a quiet population: project teams from two reorganizations ago, a group whose only owner left last spring, a SharePoint site nobody has opened since its launch week. Nobody built that on purpose. Self-service did what it was designed to do, and nobody was handed the other half of the job.
Microsoft ships three controls for that other half. They behave differently, they live in three different admin centers, and every one of them assumes somebody has already decided who answers the email. That decision is what this post is about.
Three controls, three admin centers
Group expiration sits in the Microsoft Entra admin center under Groups > Expiration. You set a lifetime in days, 30 or more, and apply it to all Microsoft 365 groups, a selected list of up to 500, or none. A tenant gets exactly one expiration policy, so "finance keeps two years, projects get one" isn't available. A Groups Administrator or User Administrator configures it, and the organization has to possess, though not necessarily assign, Microsoft Entra ID P1 or P2 licenses for the members of every group in scope.
The ownerless group policy sits in the Microsoft 365 admin center under Settings > Org settings > Microsoft 365 Groups. A group goes ownerless when its owner's account is deleted, and from then on nobody can add members or change its settings. An Exchange administrator or Groups administrator switches the policy on, and it emails the group's most active members each week asking whether they'll take ownership.
Site lifecycle management sits in the SharePoint admin center under Policies. It belongs to SharePoint Advanced Management, which Microsoft includes once a tenant assigns at least one Microsoft Copilot license and otherwise treats as a separately licensed offering. There are three policy types: site ownership (a minimum count of owners or admins; Microsoft's own example is two), inactive site, and site attestation.
What actually happens, in order
Expiration is gentler than its name. Groups in real use renew themselves when someone views or edits a file in SharePoint, reads a group message in Outlook, visits a Teams channel or views a Viva Engage post. Renewal lands around 35 days before expiry and the owner never hears about it. Email only goes out for groups nobody touched, at 30, 15 and 1 day before the date, and Microsoft says it never deletes a group before the last one is sent. A group that still isn't renewed is deleted one day after it expires and can be restored for 30 days. That window can't be changed. Thirty days after deletion, the group's Planner, site and Teams data is gone for good.
One launch detail catches people out. When you first switch expiration on, every group already older than the lifetime gets 35 days to expiry. Announce the policy before that clock starts, not after.
The ownerless policy asks; it doesn't enforce. Up to two members can accept. If nobody does by the end of the notification period you configured, the policy stops and does nothing more, and a tenant admin has to find and assign an owner by hand. The mechanics trip people up too: the sender has to be a user or group mailbox, since shared mailboxes aren't supported; recipients only see the Yes and No buttons outside the preview pane; and in a tenant with many ownerless groups, Exchange Online's limit of 10,000 sent messages per mailbox per day can throttle the notices. Limiting which members get invited, by security group, needs Entra ID P1 or P2 for each group member.
Inactive site policies read activity across SharePoint, Teams, Viva Engage and Exchange. In active mode the policy runs monthly. After three monthly notifications with no answer it does what you configured: nothing, read-only, or read-only for 3, 6, 9 or 12 months followed by archiving through Microsoft 365 Archive, provided Archive is enabled. A site owner who selects Certify site buys a year without checks. One who misses the window can't lift read-only; a tenant admin has to unlock the site. OneDrive, root sites, home sites, the app catalog and private or shared channel sites are out of scope. Simulation mode runs once and reports without enforcing anything, and every one of these policies should spend its first cycle there.
Expiration deletes. Retention decides what survives.
We hold this line harder than any other. Group expiration is housekeeping. It doesn't know what a record is. When a Microsoft Purview retention policy covers Microsoft 365 groups, the conversations and site files of an expired group stay in the retention container for the policy's period and remain recoverable through eDiscovery, even though users no longer see the group. A group mailbox on legal hold isn't permanently deleted. Without that coverage, the 30-day restore window is the whole safety net.
People who have run disposition in OpenText or SAP landscapes know the order: retention coverage first, cleanup second. Switching on expiration before the records owner has confirmed what the retention policy catches is the one sequence we won't sign off on.
Who owns sprawl
Sprawl is a service-ownership problem dressed up as an admin setting. Deloitte's Microsoft practice frames the broader challenge as closing "the gap between technology ownership and value realization," and lifecycle policy is a small, concrete case of it. Here is how we split the work:
| Decision | Owner |
|---|---|
| Whether expiration is on, the lifetime, and which groups are in scope | Microsoft 365 service owner in IT, with the records owner's sign-off |
| Where notices go for groups that have no owner | The service owner names a monitored mailbox, never one person's inbox |
| Accepting ownership, certifying sites, answering attestations | The business owner of each group or site |
| Retention coverage before anything can expire | Records owner, with counsel on holds |
| Unlocking read-only sites and reactivating archived ones | SharePoint administrators, at the business owner's request |
It reads like bureaucracy until the first renewal notice goes to a departed employee's mailbox. After that it reads like the cheapest control in the tenant.
One last distinction. Archiving a team in the Teams admin center stops team activity, can make the connected SharePoint site read-only for members, and can be reversed. Microsoft 365 Archive is a separate feature, and archiving one doesn't archive the other. Decide which one your process means before you write the process down.